Skip to content

Webhook events

What you can subscribe to, and the envelope every one of them arrives in.

The authoritative list — with the exact names to subscribe to — is served by the API itself at /api/v1/open-network/webhooks/events, and is what the event picker in the dashboard renders. Reading it is better than copying this page, because it cannot go out of date.

The envelope — identical for every event type
{
  "id": "evt_m1x9k2pQr8sT",
  "event": "booking.created",
  "occurredAt": "2026-08-12T09:41:07.412Z",
  "environment": "production",
  "partnerId": "cmruwlyja0000xfblwgefj7mv",
  "data": {
    "booking": {
      "id": "cmsq1a2b3c4d",
      "module": "activity",
      "reference": "BKG-7F3K9Q",
      "experienceId": "cmrv0activity01",
      "experienceName": "Sunset Kayak Tour",
      "status": "CONFIRMED",
      "paymentStatus": "PAID",
      "customerName": "Farhana Rahman",
      "customerPhone": "01712345678",
      "customerEmail": null,
      "quantity": 2,
      "totalTaka": 3000,
      "scheduledFor": "2026-08-20T00:00:00.000Z",
      "startTime": "2026-08-20T11:30:00.000Z",
      "endTime": null,
      "checkedInAt": null,
      "cancelledAt": null,
      "cancellationReason": null,
      "createdAt": "2026-08-12T09:41:07.238Z"
    }
  }
}

The six outer fields are the same for every event, so you can route on event, deduplicate on id and order on occurredAt before you know what the payload is. Only data varies. Booking events also carry a change object with the previous status where we knew it — PENDING → CONFIRMED is far more useful for reconciliation than just being told the current value.

One booking event per admission

Bookings across all four surfaces — activity bookings, dining reservations, event RSVPs and tickets — arrive in one normalized booking shape, with module telling you which it was. A five-ticket order produces five events, because a registration is what a gate scans and what a seat map counts.

HeaderExampleWhat it is for
X-Localoy-Signaturet=1754995200,v1=9f86d0818…HMAC-SHA256 over `{timestamp}.{rawBody}`, keyed by this endpoint's signing secret. Verify it before doing anything else.
X-Localoy-Event-Idevt_m1x9k2pQr…The event's id. THE SAME on every retry and on a replay — this is your deduplication key. Delivery is at-least-once, so you will occasionally see one twice.
X-Localoy-Event-Typebooking.createdLets you route before parsing the body.
X-Localoy-Delivery-Attempt11-based. Anything above 1 means we have tried to send you this event before.
X-Localoy-Webhook-Idcmsq6p9bu0001…Which of your endpoints this went to — the id shown in the dashboard.
X-Localoy-Delivery-Idcmsq6p9of0009…This attempt sequence. Unique per (event, endpoint), stable across retries. Quote it in a support ticket.